Skip to content

source of logs to be parsed #6

@bodik

Description

@bodik

to switch from live log to offline file

$events = Get-WinEvent -FilterHashtable @{LogName="System"; ID=7030,7045} -Oldest

$events = Get-WinEvent -FilterHashtable @{Path="system.evtx";ID=7030,7045} -Oldest

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions